Context-aware network policy enforcement
Abstract
Example methods and systems for context-aware network policy enforcement are described. In one example, a computer system may detect a request for a client device to access a destination server. The computer system may extract, from the request, connection information identifying a connection to be established for the client device to access the destination server; and map the connection information to contextual information associated with the client device or a user operating the client device, or both. Based on the contextual information, the computer system may apply one or more network policies to determine whether to allow or deny access by the client device to the destination server. In response to determination to allow the access, a first response may be generated and sent to allow establishment of the connection. Otherwise, a second response may be generated and sent to block establishment of the connection.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method for a computer system to perform context-aware network policy enforcement, wherein the method comprises:
detecting a request for a client device to access a destination server, wherein the client device resides in a first network and the destination server in a second network; extracting, from the request, connection information identifying a connection to be established for the client device to access the destination server; mapping the connection information to contextual information associated with the client device or a user operating the client device, or both; based on the contextual information, applying one or more network policies to determine whether to allow or deny access by the client device to the destination server; and in response to determination to allow the access, generating and sending a first response to allow establishment of the connection; but otherwise generating and sending a second response to block establishment of the connection.
2 . The method of claim 1 , wherein mapping the connection information to the contextual information comprises:
based on the connection information, determining identification information associated with the client device or the user, both the connection information and the identification information being obtained from an access gateway prior to detecting the request.
3 . The method of claim 2 , wherein mapping the connection information to the contextual information comprises:
based on identification information associated with the client device or the user, mapping the connection information to the contextual information.
4 . The method of claim 1 , wherein extracting the connection information comprises:
extracting the connection information that includes layer-3 protocol information or layer-4 protocol information, or both, associated with the connection.
5 . The method of claim 4 , wherein extracting the connection information comprises:
extracting the connection information that includes (a) a source address associated with an interface of an access gateway capable of acting as an intermediary between the client device and the destination server and (b) a source port number selected by the access gateway for the connection.
6 . The method of claim 1 , wherein applying the one or more network policies comprises at least one of the following:
applying the one or more network policies based on the contextual information that includes one or more of the following: hardware information associated with the client device; software information associated with the client device; a state associated with the client device; a location associated with the client device or the user; a login name associated with the user; and a role associated with the user; and in response to determination to allow the access, initiating a context-aware security scan for the connection based on the contextual information.
7 . The method of claim 1 , wherein generating and sending the first response or the second response comprises:
generating and sending the first response or second response to a firewall engine that is located along a datapath leading to the destination server to facilitate establishment of the connection based on the first response or blocking of the connection based on the second response.
8 . A non-transitory computer-readable storage medium that includes a set of instructions which, in response to execution by a processor of a computer system, cause the processor to perform context-aware network policy enforcement, wherein the method comprises:
detecting a request for a client device to access a destination server, wherein the client device resides in a first network and the destination server in a second network; extracting, from the request, connection information identifying a connection to be established for the client device to access the destination server; mapping the connection information to contextual information associated with the client device or a user operating the client device, or both; based on the contextual information, applying one or more network policies to determine whether to allow or deny access by the client device to the destination server; and in response to determination to allow the access, generating and sending a first response to allow establishment of the connection; but otherwise generating and sending a second response to block establishment of the connection.
9 . The non-transitory computer-readable storage medium of claim 8 , wherein mapping the connection information to the contextual information comprises:
based on the connection information, determining identification information associated with the client device or the user, both the connection information and the identification information being obtained from an access gateway prior to detecting the request.
10 . The non-transitory computer-readable storage medium of claim 9 , wherein mapping the connection information to the contextual information comprises:
based on identification information associated with the client device or the user, mapping the connection information to the contextual information.
11 . The non-transitory computer-readable storage medium of claim 8 , wherein extracting the connection information comprises:
extracting the connection information that includes layer-3 protocol information or layer-4 protocol information, or both, associated with the connection.
12 . The non-transitory computer-readable storage medium of claim 11 , wherein extracting the connection information comprises:
extracting the connection information that includes (a) a source address associated with an interface of an access gateway capable of acting as an intermediary between the client device and the destination server and (b) a source port number selected by the access gateway for the connection.
13 . The non-transitory computer-readable storage medium of claim 8 , wherein applying the one or more network policies comprises at least one of the following:
applying the one or more network policies based on the contextual information that includes one or more of the following: hardware information associated with the client device; software information associated with the client device; a state associated with the client device; a location associated with the client device or the user; a login name associated with the user; and a role associated with the user; and in response to determination to allow the access, initiating a context-aware security scan for the connection based on the contextual information.
14 . The non-transitory computer-readable storage medium of claim 8 , wherein generating and sending the first response or the second response comprises:
generating and sending the first response or second response to a firewall engine that is located along a datapath leading to the destination server to facilitate establishment of the connection based on the first response or blocking of the connection based on the second response.
15 . A computer system, comprising:
a processor configured to implement a network policy enforcer; and a non-transitory computer-readable medium to store (a) multiple network policies and (b) instructions executable by the processor to cause the network policy enforcer to perform the following:
detect a request for a client device to access a destination server, wherein the client device resides in a first network and the destination server in a second network;
extract, from the request, connection information identifying a connection to be established for the client device to access the destination server;
map the connection information to contextual information associated with the client device or a user operating the client device, or both;
based on the contextual information, apply one or more of the multiple network policies to determine whether to allow or deny access by the client device to the destination server; and
in response to determination to allow the access, generate and send a first response to allow establishment of the connection; but otherwise generate and send a second response to block establishment of the connection.
16 . The computer system of claim 15 , wherein the instructions for mapping the connection information to the contextual information cause the network policy enforcer to:
based on the connection information, determine identification information associated with the client device or the user, both the connection information and the identification information being obtained from an access gateway prior to detecting the request.
17 . The computer system of claim 16 , wherein the instructions for mapping the connection information to the contextual information cause the network policy enforcer to:
based on identification information associated with the client device or the user, map the connection information to the contextual information.
18 . The computer system of claim 15 , wherein the instructions for extracting the connection information cause the network policy enforcer to:
extract the connection information that includes layer-3 protocol information or layer-4 protocol information, or both, associated with the connection.
19 . The computer system of claim 18 , wherein the instructions for extracting the connection information cause the network policy enforcer to:
extract the connection information that includes (a) a source address associated with an interface of an access gateway capable of acting as an intermediary between the client device and the destination server and (b) a source port number selected by the access gateway for the connection.
20 . The computer system of claim 15 , wherein the instructions for applying the one or more network policies cause the network policy enforcer to perform at least one of the following:
apply the one or more network policies based on the contextual information that includes one or more of the following: hardware information associated with the client device; software information associated with the client device; a state associated with the client device; a location associated with the client device or the user; a login name associated with the user; and a role associated with the user; and in response to determination to allow the access, initiate a context-aware security scan for the connection based on the contextual information.
21 . The computer system of claim 15 , wherein the instructions for generating and sending the first response or the second response cause the network policy enforcer to:
generate and send the first response or second response to a firewall engine that is located along a datapath leading to the destination server to facilitate establishment of the connection based on the first response or blocking of the connection based on the second response.Join the waitlist — get patent alerts
Track US2022116379A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.